3 ms·
The collab_2.png screenshot shows `User-Agent: ... Slack/4.1.2 ... Electron/6.0.10 ...`, so it's their own desktop app doing the https://slackb.com/.. https://s
by terom 7y ago
The collab_2.png screenshot shows `User-Agent: ... Slack/4.1.2 ... Electron/6.0.10 ...`, so it's their own desktop app doing the https://slackb.com/.. https://slackb.com/... HTTP 301 -> https://*.burpcollaborator.com https://*.burpcollaborator.com request. Perhaps their client implements its own quirky redirect-following, which keeps the the original `Cookie: ...` headers in the redirected request?
I find it hard to believe that any browser would keep the original `Cookie: ...` headers in a redirected request to a different origin.
- londons_explore 7y agoSome proxies follow redirects... It enables devs to do things like "redirect request to the old server", and the client never needs to know (which is important for maintaining compatibility with an old api) In that case, I'd expect all cookies etc. to be forwarded.
- JangoSteve 7y agoInteresting! That's definitely something I missed, thank you. I still wouldn't expect an Electron app to subvert basic browser sandboxing by default, particularly where they wouldn't have expected to need to redirect users to other domains with cookies intact. It seems like they'd need to go out of their way to enable that. I wonder if it has to do with the sign-in tokens they send or otherwise allowing the user to move between the browser and the app within their account. For example, when you're in the app and click "Manage Users" and it sends you to a management dashboard in the browser. or when you click a link with an auth token in the browser and it launches you into the app.